Skip to content

chore(r5): archive the scorecard corpus and clean path leaks (#837) - #1216

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/r5-archive-scorecards
Oct 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/r5-archive-scorecards

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Rebased onto main after #1213 merged (squash commit 9d629d11, 2026-10-09T09:21Z). git range-diff shows the commit unchanged (=). main differs from #1213's head ed4f98a3 only in docs/AFFIRMATION.adoc and docs/affirmations/AFFIRMATION-2026-10-07.adoc (#1212's follow-up 76773445), so the measurements below that name the base ed4f98a3 still hold for main.

Ruling R5 on #837 (owner, 2026-10-09): option B, with the §4 path-leak clean first. This PR is increment 1 of three. It freezes the spec scorecard corpus into a tombstoned archive. It does not translate the records into deeds.

  • Leak clean, before the move. 47 lines in the 29 *.scorecard.a2ml records cited the machine-local prefix /home/user/standards/ (50 occurrences: 25 evidence, 12 system and 10 effects lines). Each prefix is removed, so every path is now repo-relative. The one bare root reference (toolchain-readiness-grades, "under /home/user/standards") now reads "under the repository root". The full file:line list is below.
  • Record hygiene, deletion and repointing only. Each record's "Regenerate the dashboard with: just scorecards" header line is deleted, because that recipe is already gone. Each # Schema: comment now points at the archived schema (28 files; estate-constitution has none). The schema's $id is a historical identifier and is left as it is. No fact is added to any .a2ml file.
  • The move. .machine_readable/scorecards/ (29 records + scorecard.schema.json) moves with git mv to .machine_readable/archive/scorecards-v1/. All 30 are renames, with history kept. A new README.adoc there is the tombstone: frozen, do not edit, add or convert; why it was archived; what changed on the way in; what replaces it; and what it is not (the verisim-data per-repo RSR scorecards, and the OpenSSF Scorecard workflow).
  • Consumers repointed. .hypatia-baseline.json (the SD022 entry's file), docs/BADGE-CRITERIA-SPEC.adoc, 1-formats/k9/spec/MIGRATION-1058.adoc and REGISTRY.adoc ("What stays, frozen").
  • Decision record. 1-formats/deed/mappings/scorecard-corpus-decision.adoc goes from "awaiting ruling" to RULED: option B. A new §5 records the three increments and what each one closes.
  • Two guards learn the archive, narrowly. scripts/check-canonical-names.sh and both modes of .githooks/validate-bot-directives.sh now skip .machine_readable/archive/scorecards-v1/*.scorecard.a2ml. They do not skip the archive README, any other file there, or a sibling archive. The records are assessments that cite the names and tools of their day. They are not live directives, and the README forbids editing them.

Refs #837. It does not close it: increments 2 and 3 remain (see Notes).

Type of change

  • 🐛 Bug fix. validate-bot-directives.sh scan mode (what pre-push runs without a diff) exits 1 on the base tree: "Codex" in k9-coordination-protocol.scorecard.a2ml L23 is a historical assessment, not a directive. It exits 0 after this PR.
  • ✨ New feature. No new capability. The tombstone is documentation.
  • 💥 Breaking change. The old path has no remaining consumer in this repo. Every consumer found with git grep is repointed, and the just scorecards recipe and its builder were already gone before this PR. Callers outside this repo, if any, are not covered by that search.
  • 🕳️ Soundness fix. The guard changes widen nothing beyond the archived records, and planted positives pin that (see verification).
  • 📖 Documentation. A tombstone README, the ruling recorded in the decision spec, and four consumer docs repointed.
  • 🧹 Refactor / tech debt. 29 records frozen and leak-free; ruled debt on DEED conversion campaign — tracking & acceptance criteria (.a2ml → .deed) #837 paid down.
  • ⚡ Performance. Not applicable.
  • 🔧 Build / CI / tooling. Two hook scripts gain one exclusion each; two hook tests gain cases.

📌 New pins

  • Head SHA: afb8a4f6fcc4c66124964923b9fbcbad6505236c
  • No pins added or changed. No uses: SHA, no actions.lock entry, no lockfile record, no container digest.

How has this been verified?

All commands were run locally in the worktree (Debian 13, WSL2) with MISE_DISABLE=1.

  • After the rebase onto 9d629d11: bash scripts/check-canonical-names.sh origin/main → no deprecated names reintroduced. wave6-canonical-names-test.sh → 8 passed, 0 failed. validate-bot-directives-test.sh → 10 passed, 0 failed. validate-bot-directives.sh in scan mode → All files validated. git range-diff ed4f98a3..321f6165 origin/main..HEAD → 1: 321f6165 = 1: afb8a4f6.

  • bash scripts/run-shell-test-suite.sh → All 80 test file(s) passed., rc 0. That includes both edited tests.

  • bash scripts/tests/wave6-canonical-names-test.sh → 8 passed, 0 failed. The new case reproduces the real move: a record is committed, git mv'd into the archive and edited, so the diff is a rename carrying a + line under the new path.

    • Mutant: deleting the exclusion line from the guard gives 7 passed, 1 failed, and the failure is exactly the archived-record case.
    • Planted positives: the archive README and a sibling archive/scorecards-v2/ are still blocked.
  • bash scripts/tests/validate-bot-directives-test.sh → 10 passed, 0 failed. It has 5 new cases: staged-mode archived record → 0; archive README → 1; sibling archive → 1; scan-mode archived record → 0; scan-mode live .deed directive beside the archive → 1.

    • Mutant: removing both exclusions gives 8 passed, 2 failed, and the failures are exactly the two archived-record cases.
  • The guards on the real change:

    • bash scripts/check-canonical-names.sh ed4f98a3 → no deprecated names reintroduced, rc 0. With the exclusion removed, it flags 0-ai-gatekeeper-protocol and release-pre-flight, so the exclusion is load-bearing and is reached through the rename.
    • INPUT_PATH=. bash .githooks/validate-bot-directives.sh (scan mode) → All files validated, rc 0.
    • The same hook on a git archive of the base ed4f98a3 → ERROR: .machine_readable/scorecards/k9-coordination-protocol.scorecard.a2ml contains deprecated bot directives, rc 1.
  • No absolute path is left. grep -E '/home/|/Users/|/root/|/tmp/|/mnt/|C:\\|~/' over the 29 archived records → 0 matches. git ls-files '*.scorecard.a2ml' → 29, all under archive/scorecards-v1/ (acceptance item 1 of the decision spec, §3).

  • Every added link resolves. Each new link: target in the four edited or new .adoc files was tested with -e relative to its file: 6 links, 0 missing.

  • .hypatia-baseline.json still parses (jq -e .), and its one changed value is the file of the SD022 entry. Its entry count is unchanged by this PR. The ratchet's 205 -> 189 reading below is the base's own delta from main.

  • bash scripts/check-exemption-ratchet.sh origin/main → Exemption ratchet: OK. bash scripts/check-standards-map.sh → GATE D PASSED. apply-baseline-test.sh, filter-sarif-by-baseline-test.sh and hypatia-blocking-gate-test.sh → rc 0.

  • .githooks/docstring-scan.sh --staged --check → rc 0. The modified is_excluded and the new cks are both documented.

  • Pre-commit and pre-push passed in full, including gitleaks, canonical names and bot directives. The first commit attempt was refused by commit-msg (subject was 78 characters, limit 72) and was shortened. No hook was bypassed.

  • git diff --cached --check → clean.

Checklist

  • My commits are signed (git commit -S). git log --show-signature reports a good ED25519 signature on afb8a4f6.
  • I ran the project's own checks/tests locally and they pass. See above.
  • New files carry the correct SPDX-License-Identifier. The one new file, the archive README.adoc, is prose and carries CC-BY-SA-4.0. No existing header is changed.
  • Docs are updated, and no public claim now overstates what the code does. The README and §5 say plainly that the (assessment …) clauses and the estate-audit emitter do not exist yet.
  • I have not introduced a soundness hole, or I have flagged where I might have. The two guard exclusions are the only widening. They are fenced to *.scorecard.a2ml in one directory, and planted positives prove that nothing else there, and no sibling archive, escapes.

Notes for reviewers

  • Reduced scope, stated (§5b):
    • Acceptance item 2, one (assessment …) clause per spec_id, is increment 2. It needs a <repo>_chora.deed for this repository, which does not exist yet. Whether the canon repo's own deed carries a canon clause is an open question for that increment.
    • Acceptance item 3, a forward link from each archived record, will be met by the directory tombstone, not by editing each record: writing a link into a frozen .a2ml would add content to a retired format. The tombstone gains the forward link when the deed exists.
    • Increment 3 is the estate-audit emitter for future assessments.
  • Why the leak list is here and not in estate-residue-ledger.tsv: the decision spec's §4 suggested the residue ledger, but that file is generated by scripts/spine/board.awk and checked by verify-board.sh, so a hand-added row would be lost at the next regeneration.
  • 47 lines here, 48 in the R5 register. The register comment on DEED conversion campaign — tracking & acceptance criteria (.a2ml → .deed) #837 (2026-09-19) counted 48 leak lines, on main at 000b9f6b. One of them, an evidence line in 0-ai-gatekeeper-protocol, was rewritten by fix(main-red): repair the post-#899 red main (code + baseline triage + regen) #947 (7b05a323, 2026-09-22), so 47 remained at the base, and all 47 are cleaned here. After this PR, 0 remain.
  • The corpus measured 29 files, not the "70+" in the decision spec's title. The title is left as it was, and §5 records the measured count.
  • Left as they are, on purpose: 0-canon/COMPLIANCE-DASHBOARD.adoc (a frozen snapshot), RSR-SPEC-v2.adoc L147 and rsr-criteria-v2.a2ml L65 (a different scorecard corpus), canon.lock (its only "scorecard" hit is the OpenSSF workflow), and the data line hypatia-rules L69, which mentions just scorecards as assessment evidence rather than as an instruction.
The 47 cleaned lines (file:line on the base ed4f98a3, under .machine_readable/scorecards/; each line held the prefix named in the Summary; content omitted)
0-ai-gatekeeper-protocol.scorecard.a2ml:26
0-ai-gatekeeper-protocol.scorecard.a2ml:36
0-ai-gatekeeper-protocol.scorecard.a2ml:43
0-ai-gatekeeper-protocol.scorecard.a2ml:51
0-ai-gatekeeper-protocol.scorecard.a2ml:65
accessibility.scorecard.a2ml:17
accessibility.scorecard.a2ml:33
accessibility.scorecard.a2ml:56
accessibility.scorecard.a2ml:63
adoption-readiness-grades.scorecard.a2ml:17
adoption-readiness-grades.scorecard.a2ml:75
agentic-a2ml.scorecard.a2ml:17
agentic-a2ml.scorecard.a2ml:54
anchor-a2ml.scorecard.a2ml:64
ecosystem-a2ml.scorecard.a2ml:17
ecosystem-a2ml.scorecard.a2ml:33
ecosystem-a2ml.scorecard.a2ml:77
foundations-readiness-grades.scorecard.a2ml:17
hypatia-rules.scorecard.a2ml:17
k9-coordination-protocol.scorecard.a2ml:72
k9-svc.scorecard.a2ml:17
k9-svc.scorecard.a2ml:26
k9-svc.scorecard.a2ml:56
k9-svc.scorecard.a2ml:63
k9-svc.scorecard.a2ml:65
k9-svc.scorecard.a2ml:74
k9-svc.scorecard.a2ml:122
meta-a2ml.scorecard.a2ml:17
meta-a2ml.scorecard.a2ml:75
meta-a2ml.scorecard.a2ml:98
neurosym-a2ml.scorecard.a2ml:45
overlay-protocol.scorecard.a2ml:68
release-pre-flight.scorecard.a2ml:15
release-pre-flight.scorecard.a2ml:24
release-pre-flight.scorecard.a2ml:33
release-pre-flight.scorecard.a2ml:42
release-pre-flight.scorecard.a2ml:44
release-pre-flight.scorecard.a2ml:49
release-pre-flight.scorecard.a2ml:51
release-pre-flight.scorecard.a2ml:60
release-pre-flight.scorecard.a2ml:65
release-pre-flight.scorecard.a2ml:74
release-pre-flight.scorecard.a2ml:83
release-pre-flight.scorecard.a2ml:85
toolchain-readiness-grades.scorecard.a2ml:17
toolchain-readiness-grades.scorecard.a2ml:38
toolchain-readiness-grades.scorecard.a2ml:54

🤖 Generated with Claude Code

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 3 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 07563db6-9e1b-4285-b70a-43c2d998885d

📥 Commits

Reviewing files that changed from the base of the PR and between 9d629d1 and afb8a4f.


📒 Files selected for processing (40)
  • .githooks/validate-bot-directives.sh
  • .hypatia-baseline.json
  • .machine_readable/archive/scorecards-v1/0-ai-gatekeeper-protocol.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/README.adoc
  • .machine_readable/archive/scorecards-v1/a2ml-templates.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/accessibility.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/adoption-readiness-grades.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/agentic-a2ml.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/anchor-a2ml.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/avow-protocol.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/axel-protocol.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/component-readiness-grades.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/contractiles.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/did-you-actually-do-that.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/ecosystem-a2ml.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/ensaid-config.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/estate-constitution.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/form-fill-provenance.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/foundations-readiness-grades.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/hypatia-rules.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/k9-coordination-protocol.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/k9-svc.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/meta-a2ml.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/neurosym-a2ml.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/overlay-protocol.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/playbook-a2ml.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/publication-pre-flight.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/release-pre-flight.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/rhodium-standard-repositories.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/scorecard.schema.json
  • .machine_readable/archive/scorecards-v1/session-management-standards.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/state-a2ml.scorecard.a2ml
  • .machine_readable/archive/scorecards-v1/toolchain-readiness-grades.scorecard.a2ml
  • 1-formats/deed/mappings/scorecard-corpus-decision.adoc
  • 1-formats/k9/spec/MIGRATION-1058.adoc
  • REGISTRY.adoc
  • docs/BADGE-CRITERIA-SPEC.adoc
  • scripts/check-canonical-names.sh
  • scripts/tests/validate-bot-directives-test.sh
  • scripts/tests/wave6-canonical-names-test.sh


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37909784377

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] debt rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl (fail) — K9-N001 K9-S004 K9-S005 K9-S014 (grandfathered; touching it makes it blocking)
[validate-k9] 14 conforming, 1 grandfathered (layer all, contract v1.0.0)

Base automatically changed from chore/retire-a2ml-registry-gates to main October 9, 2026 09:21
Ruling R5 on #837 (owner, 2026-10-09): option B, with the section 4
leak clean first. This is increment 1 of three.

- Remove machine-local absolute paths from 47 lines (25 evidence,
  12 system, 10 effects) of the 29 *.scorecard.a2ml records, before
  the move, so the archive is clean from its first commit.
- Drop the generator header from each record (the recipe is gone) and
  repoint each "# Schema:" comment at the archived schema.
- Move .machine_readable/scorecards/ (29 records + schema) to
  .machine_readable/archive/scorecards-v1/ and add a README tombstone.
- Repoint the four consumers: .hypatia-baseline.json,
  docs/BADGE-CRITERIA-SPEC.adoc, 1-formats/k9/spec/MIGRATION-1058.adoc,
  REGISTRY.adoc.
- Record the ruling and the three increments in
  1-formats/deed/mappings/scorecard-corpus-decision.adoc section 5.
- Exclude the archived records (only *.scorecard.a2ml, not the README
  and not a sibling archive) from check-canonical-names.sh and from
  both modes of validate-bot-directives.sh. Scan mode of the latter was
  red on the base tree on k9-coordination-protocol.scorecard.a2ml; it
  passes now. Planted-positive tests pin the narrow scope; removing
  either exclusion fails exactly the archive case.

Pending: increment 2 (one (assessment ...) clause per spec_id) needs a
chora deed for this repository; increment 3 is the estate-audit
emitter.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML
@hyperpolymath
hyperpolymath force-pushed the chore/r5-archive-scorecards branch from 321f616 to afb8a4f Compare October 9, 2026 09:22
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37910884655

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] debt rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl (fail) — K9-N001 K9-S004 K9-S005 K9-S014 (grandfathered; touching it makes it blocking)
[validate-k9] 14 conforming, 1 grandfathered (layer all, contract v1.0.0)

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath marked this pull request as ready for review October 9, 2026 09:24
@hyperpolymath
hyperpolymath merged commit 8496854 into main Oct 9, 2026
71 checks passed
@hyperpolymath
hyperpolymath deleted the chore/r5-archive-scorecards branch October 9, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant